Vendor: Secure-IC Category: Post Quantum

ML-KEM / ML-DSA Post-Quantum Cryptography IP

ML-KEM (Crystals-Kyber) and ML-DSA (Crystals-Dilithium) are Post-Quantum Cryptographic (PQC) algorithms, meaning they are mathema…

CRYSTALS-Dilithium (ML-DSA) View all specifications

Overview

ML-KEM (Crystals-Kyber) and ML-DSA (Crystals-Dilithium) are Post-Quantum Cryptographic (PQC) algorithms, meaning they are mathematically designed to be robust against a cryptanalytic attack using a quantum computer. Both have been standardized by the NIST in it post-quantum cryptography project.

The security of ML-KEM and ML-DSA algorithms is based on the hardness of solving the learning-with-errors (LWE) problem over module lattices.

ML-KEM belongs to Key Encapsulation Mechanism (KEM) family, KEM is an encryption technique designed to secure symmetric cryptographic keys (e.g. AES key) for transmission using asymmetric algorithms (e.g. RSA in classical cryptography), or for more security, using post-quantum cryptography with ML-KEM.

ML-DSA is a digital signature algorithm.

The Lattice Hardware accelerator can be used to realize the ML-KEM Key Encapsulation Mechanism and the ML-DSA signature scheme, with the appropriate software library.

To implement the ML-KEM and ML-DSA functions, five elements are needed:

  • The Hardware Lattice Accelerator SCZ_IP_PQC_Lattice and its dedicated RAM
  • A Software library which is running on the Securyzr iSE CPU, in case the IP is intergated in a SoC as a stand-alone IP and not in a

Secure-IC iSE, the software library then must run on the SoC CPU

  • A SHA3/SHAKE Hardware accelerator (*)
  • A DMA to optimize memory accesses (*)
  • A TRNG for random seed generation (*)

(*) The TRNG, DMA and SHA3+SHAKE Hardware IPs are available as part of Secure-IC’s Crypto Solutions. They are not provided in a context of SCZ_IP_PQC_Lattice standalone IP.

Key features

ML-KEM and ML-DSA have been selected by the NIST post-quantum cryptography project.
The US National Security Agency also recommends to implement those algorithms in its Commercial National Security Algorithm Suite 2.0 (CNSA 2.0).
The present product is based on the version of ML-KEM and ML-DSA selected by the NIST at the end of round 3 and is aligned with NIST reference implementation.

Security features

  • ML-KEM-512, ML-KEM-768, ML-KEM-1024.
  • ML-DSA-II, ML-DSA-III, ML-DSA-V.
  • Implementation protected against Side-Channel Attack (Key Generation and Key Decapsulation operations are sensitive):
  • Simple Power Analysis (SPA)
  • Differential Power Analysis (DPA)
  • Differential Electromagnetic Analysis (DEMA)
  • Correlation Power Analysis (CPA)
  • Correlation Electromagnetic Analysis (CEMA)
  • Optional: health tests for integrity verification.

Other features

  • Hybrid hardware-software solution.
  • Optimized in performance or power/area.
  • Performs Key Generation, Key Encapsulation and Key Decapsulation functions
  • Performs Key generation, Signature and Verification.
  • Memory can be shared or dedicated.
  • Easy to integrate into the system thanks to AMBA AXI wrapper.
  • The control interface of the hardware accelerator is the AMBA AXI interface

Block Diagram

Applications

  • The ML-KEM  IP and ML-DSA may be used both in quantum computing and classical computing context for:
    • Secure communications systems
    • Secure Boot
  • For Signature, ML-DSA ensures
    • Keys generation
    • Signature
    • Verification
  • For Key Encryption Mechanism, ML-KEM ensures:
    • Key Generation
    • Key Encapsulation
    • Key Decapsulation

What’s Included?

  • RTL of the AMBA wrapper 
  • VHDL RTL source code
  • ML-KEM / ML-DSA software libraries
  • Self-checking RTL Testbench based on reference scenario for simulation

Specifications

Identity

Part Number
SCZ_IP_PQC_Lattice
Vendor
Secure-IC
Type
Silicon IP

Security

Crypto Algorithm
CRYSTALS-Dilithium (ML-DSA)

Videos

Video 1

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: France

Learn more about Post Quantum IP core

How to design secure SoCs Part IV: Runtime Integrity Protection

In previous articles, we gave an overview about secure SoC architectures (Part I), about the importance of key management (Part II) and secure boot (Part III) - the first line of defense. Part IV of the series focuses on runtime integrity protection, a paramount, ensuring the application remains secure even during active operation.

How to design secure SoCs Part IV: Runtime Integrity Protection

SoC designers are increasingly challenged to integrate robust security measures into their designs. Modern connected devices, such as automotive Electronic Control Units (ECUs), Internet of Things (IoT) nodes, and industrial control systems, face increasing susceptibility to cyberattacks. This escalating threat landscape underscores the critical importance of mandatory security requirements.

Nine Compelling Reasons Why Menta eFPGA Is Essential for Achieving True Crypto Agility in Your ASIC or SoC

Today’s world is already overly complicated to provide robust product security, with extremely motivated hackers creating novel threats exposing new vulnerabilities every day. But considering tomorrow’s world with the looming threat of quantum computing, expanding AI possibilities and rapidly evolving regional regulations and export control risk with severe financial penalties, this is a daunting challenge.

Providing protection against EMFI attacks

This Agile Analog blog post is focused on describing the dangers of Electromagnetic Fault Injection (EMFI) attacks and outlining the importance of EMFI sensors that are designed to provide protection.

Deploying StrongSwan on an Embedded FPGA Platform, IPsec/IKEv2 on Arty Z7 with PetaLinux and PQC

The objective of this article is to present and analyze a concrete IPsec/IKEv2 deployment on an FPGA-based embedded Linux system. Using an Arty Z7 FPGA platform with PetaLinux and StrongSwan, the focus is on system-level integration rather than protocol theory: how the IPsec stack is built and deployed, how classical and post-quantum key exchange are integrated without modifying standardized protocols, and what architectural trade-offs arise when moving cryptographic operations into programmable logic.

Frequently asked questions about Post-Quantum Cryptography IP cores

What is ML-KEM / ML-DSA Post-Quantum Cryptography IP?

ML-KEM / ML-DSA Post-Quantum Cryptography IP is a Post Quantum IP core from Secure-IC listed on Semi IP Hub.

How should engineers evaluate this Post Quantum?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Post Quantum IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP